From a Spreadsheet to a Process That Holds Up
Almost every compliance topic begins in a spreadsheet. That works – until documentation duties, deadlines and several contributors come into play. In these practice guides we show, for fifteen typical tasks, what the workflow looks like today, where it breaks down and how the same process is set up digitally.
Why spreadsheets eventually work against you
Excel, Word and a shared mailbox are excellent tools – for content that rarely changes and that a single person is responsible for. Compliance is the opposite of that: the content ages continuously, several departments contribute, deadlines run regardless of your attention, and when it matters you have to demonstrate not only a result but the path that led to it.
This is exactly the point at which the effort tips over. Not because the spreadsheet is poorly maintained, but because structurally it knows nothing about responsibility, currency, version and evidence. Every article in these practice guides therefore follows the same structure: the real current process, the problems that arise from it, the target process in clear steps – and a before/after comparison you can measure your own situation against.
All practice guides
Fifteen Processes, Fifteen Ways Out of Doing It by Hand
Every article describes a concrete workflow – from the records of processing activities through the protection needs assessment and the use of AI to the question of why a software rollout fails because of people and not because of features.
Records of Processing Activities in Excel
preeco | data protection
One file, one person in charge, contributions by email: why records of processing activities in Excel do not carry the evidence required by Art. 30 GDPR – and how the process runs instead.
Deletion Concept: From Document to Routine
preeco | data protection
A deletion concept that nobody opens again once it is written meets no obligation. This is how retention periods become recurring, documented procedures.
Data Subject Requests Without a Shared Mailbox
preeco | data protection
The one-month deadline in Art. 12 GDPR starts when the request arrives – not when someone notices it. Why a shared mailbox is the wrong place for it.
72 Hours: The Data Breach as a Process
preeco | data protection
A phone call, a note on a pad, a spreadsheet: when it counts, preparation decides. This is what a reporting process looks like that meets the deadline in Art. 33 GDPR.
DPA Folders and Vendor Reviews
preeco | data protection
Contracts as PDFs on the file share, review dates carried in your head: how processing on behalf becomes verifiable without keeping a second calendar.
Training Records Without an Attendance Sheet
preeco | data protection
The question "Who is overdue?" should not be manual work. From the scanned certificate to a training status you can call up at any time.
Risk Analysis and DPIA With a Method
preeco | data protection
Every assessment a new Excel matrix, every matrix a different scale. How individual cases turn into a methodology you can reuse.
Building an ISMS Without an Excel Graveyard
preeco | information security
A controls spreadsheet, an action plan, an evidence folder – three places, one audit. How ISO 27001 and BSI IT-Grundschutz come together in a single place.
From IT Inventory to Asset Landscape
preeco | information security
IT maintains an inventory list, data protection maintains a system list. Why both mean the same thing – and what a shared inventory changes.
Receiving Reports: Why a Mailbox Does Not Hold Up
preeco | whistleblower
A compliance mailbox knows senders, metadata and log files. For the protection of whistleblowers, that is precisely the problem.
Determine Protection Needs Instead of Estimating Them
preeco | data protection
Low, medium, high – set in a single meeting in which three people hold three different yardsticks in mind. How a gut feeling becomes a method you can explain.
AI in Data Protection: A Draft, Not a Result
preeco | data protection
A language model produces drafts, not evidence. Where in the workflow the draft is created, who reviews it and how you recognize one you must not adopt.
AI in the Reporting Office: Confidentiality First
preeco | whistleblower
The deadlines of the German Whistleblower Protection Act (HinSchG) are running, and the content of a report still must not circulate freely. Why the feature ships switched off.
AI Without Vendor Lock-In
All products with AI features
preeco does not bring a model of its own. What it means to hold the provider, the key and the contract in your own hands – and which work that leaves with you.
Rolling Out Software: Acceptance Decides
All products
Rollouts rarely fail because of features. Which feelings stand in the way, what an interface can do about them – and what it cannot.
Walk Through Your Process With Us
In 30 minutes we look at your current workflow and show how it is mapped in preeco – without sales pressure.